Screenata

SOC 2 · HIPAA · ISO 27001

Get ready for SOC 2.
With help at every step.

Get a clear plan, founder-led support, and an AI agent that helps prepare policies and collect evidence. Keep your team focused on building while you work toward your audit.

30 minutes with the founder · Written next steps · No purchase required

Founder-led onboardingShared Slack channelYour choice of auditor
SOC 2HIPAAISO 27001ISO 42001GDPR

Animated product demo: Screenata scans your systems, assesses SOC 2 readiness, remediates gaps, collects your review and sign-off, and delivers a signed audit package to your auditor.

A person to turn to

Founder-led support. From your first connection to audit preparation.

Work directly with Screenata’s founder to connect your systems, review generated policies, and build your first evidence plan. Founder-led onboarding is included for our current cohort, with scope agreed before you sign.

A shared Slack channel with the founder.

Your team gets a shared Slack channel with Screenata’s founder for setup questions, product help, and blockers. We agree support hours and check-in times during onboarding.

What we work on together

  • Help connecting your cloud, code repositories, and identity provider
  • Company profile, audit scope, and a system description scope draft
  • A walkthrough of generated policies for your review
  • An evidence plan with the next actions and owners
  • A readiness check before your auditor starts
  1. 01

    Agree your scope

    Start with the customer request, your systems, and your target date. Agree what the platform, your team, and any partner will cover.

  2. 02

    Prepare and review

    Connect your systems. Vera drafts policies and gathers evidence; we help you work through setup and the next actions. Your team reviews and approves.

  3. 03

    Prepare for auditor review

    Check readiness and organize the evidence package. Your independent auditor reviews the evidence and issues the report.

What your team, Screenata, and your auditor each own

Your team provides access and accurate information, reviews and approves policies, operates its controls, and fixes infrastructure gaps. Your independent auditor decides whether the evidence is sufficient and issues the report.

Infrastructure remediation, advisory beyond the agreed program, and hands-on audit fieldwork support are scoped separately with a delivery partner when needed. The independent audit fee is separate.

Start with a free readiness review
SOC 2 Type II program100%
  1. Scan
  2. Policies
  3. Evidence
  4. Gaps
  5. Pack
Ready for your auditor

From first scan to audit report.

Vera writes the policies, collects the evidence, works through the gaps with your team, and assembles a signed audit package. You approve; your auditor issues the report.

Your compliance program

Every module included.

Scope agreed before signing

One program, every module.

Policies, evidence, monitoring, and audit preparation in one program. We work through your scope and support needs with you, then put the proposal in writing.

okta-mfa.json

Jun 30, 06:00 · Okta API

CC6.1
SHA-256 · RFC 3161 · signed
Verified

A report your customers can trust.

Every artifact is mapped to a control, dated, and signed, so any auditor can verify it independently. When an enterprise buyer's security team reads it line by line, the proof holds up.

“I really like… the focus on reducing manual work instead of just giving users another compliance dashboard to manage. The AI agent approach… feels more like having an assistant working with you instead of just showing you tasks.”
GRC consultantUsing Screenata with clients

01 · Policies

Scan first. Then write what you can prove.

Vera assembles context from GitHub, AWS or GCP, your IdP, and existing evidence before a single policy is written. The overpromise checker flags hard commitments unsupported by what she found, before your auditor does.

  • Policies grounded in real IAM policies, branch protection, and MFA settings
  • Overpromise detection, the #1 audit failure mode, caught at draft time
  • All 8 SOC 2 foundational deliverables, right-sized for startup teams
Access Control Policy · draft
2 flagged

Acme Corp enforces multi-factor authentication through Okta for all administrative access to production systems. verified

Production access is reviewed quarterly by the security team to remove stale entitlements. overpromise

Vera flagged this claim

No quarterly access review evidence found in the last 12 months across Okta and GitHub. Soften to "periodic reviews as needed", or commit to quarterly and let me schedule them.

Soften languageSchedule quarterly review

02 · Evidence

Automate evidence collection beyond APIs.

API integrations are table stakes and cover about 30–40% of a SOC 2. The rest lives in screens and walkthroughs that other platforms hand back to you as a to-do list. Screenata captures those too, and evidence collected once counts toward every framework it satisfies.

01

API Automation

Cloud, code, and identity providers scanned on a schedule. Every check maps to a control and is signed on arrival.

What every platform does.

Weekly scan

Providers

  • Okta
  • AWS
  • GitHub
  • Google Cloud
  • Datadog

Checks running

  • MFA enforced for admin accountssigned 6:00 AM
  • S3 default encryption on all bucketssigned 6:00 AM
  • Branch protection on mainsigned 6:00 AM
  • CloudTrail retention 365 dayssigned 6:00 AM
  • Alerting on production errorssigned 6:00 AM

Controls satisfied

  • CC6.1Passing
  • CC6.7Passing
  • CC8.1Passing
  • CC7.2Passing
  • CC1.4Passing
650+ checks · 60+ providers · on a schedule

02

Screenshot Automation

Settings pages and admin consoles with no API, the evidence teams still screenshot by hand. Click the extension, or let a procedure trigger it on schedule. Captured, redacted, quality-checked, signed, filed.

Where most platforms hand the work back to you.

Screenshot automation
Screenata extension
CapturingCapturedCaptured 2026-10-07 06:00:12 UTC

What happens next

  1. Capture1440×900 · time-stamped
  2. Redact1 field masked
  3. Vision checkQuality 9 / 10
  4. SignSHA-256 · RFC 3161
  5. FileCC8.1 · Change management
Re-captured on schedule · evidence never goes stale

03

Procedure Automation

Multi-step work with an owner per step, proof attached as you go, and a sign-off at the end. The run itself becomes the signed evidence record.

Where most platforms hand the work back to you.

Quarterly backup restore test
Trigger

Quarterly schedule

Apr 1 · 09:00run #4
Step

Restore snapshot to staging

Sarah log
Vera

Compare row counts

Running…2,418,902
Condition

Counts match?

Approval

CTO signs off

MarcusPendingWaiting
Evidence

Signed record

A1.2
If noskip

Open incident

yesyesno

Vera: Counts match on both sides. Routed to Marcus for sign-off.

Results recorded as you work · every run is a signed record

Plus inbox ingestion: forward an email or drop a file in Slack and it files itself.

The evidence collector extension

03 · Slack & email

Compliance requests without another login.

Your team shouldn't have to sign in to one more platform to finish a request. Files dropped in Slack or emailed to your workspace address are filed as evidence and matched to the right test. Nobody has to open the dashboard.

  • Email your workspace address: attachments are filed as evidence, and Vera replies
  • Owners get a reminder before work is due and an alert when it's late
  • Daily freshness checks: fresh, stale at 90 days, expired at 120
Slack, Acme Corp

compliance

8 members · pinned: SOC 2 program

Today
Screenata
ScreenataAPP6:30 AM

Daily compliance briefing · Mon Apr 28

  • • Readiness 84% (+12 vs last week)
  • • 1 blocker: CC6.1, Okta access review evidence stale (92d)
  • • 2 warnings: CloudTrail Q2 export missing, S3 encryption check needs re-run
  • Next: ask @priya for the access review export
Screenata
ScreenataAPP9:04 AM

Weekly cloud scan · 500 checks

  • • 499 passed · 1 new finding
  • • S3 bucket logs-archive missing default encryption
  • Drafted remediation ticket, needs your approval to apply.
Reply to #compliance

04 · Proof

One sentence. One claim. One test. One signed artifact.

Screenata links each policy sentence to the control it satisfies, the test that checks it, and the signed evidence that proves it. Your team can see why a requirement exists and exactly what proves it. Your auditor can verify the artifact outside Screenata.

  • Trace any policy, claim, control, or test through to its evidence
  • Each test says what to provide and how your auditor will judge it
  • Per-file SHA-256 manifests, RSA/ECDSA signatures, RFC 3161 timestamps
  • Open Evidence Signing, the open evidence spec, with a free verify CLI

Policy sentence

Administrative access requires MFA through Okta.

Access Control Policy / §3.2

extracts a testable claim

Policy claim

MFA enforced for admin accounts

CC6.1 · IA-2 · IMPLEMENTED

verified by a control test

Control test

Okta MFA policy verification

Native API check · 24h freshness

produces a signed artifact

Evidence artifact

Signed Okta API response

SHA-256 + RFC 3161 timestamp

SHA-256RFC 3161verify outside Screenata

How it runs

A week of compliance, run by Vera.

Scheduled agents do the checking, following up, and filing. You approve the parts that need a human.

  1. Monday · 6:00 AM

    Cloud and code scan

    Checks run across AWS or GCP, GitHub, and your identity provider. Every result maps to a control.

    499 / 500 passed
  2. Every day · 6:00 AM

    Evidence freshness check

    Each artifact is checked against its window. Fresh, stale at 90 days, expired at 120.

    3 going stale
  3. Every day · 6:30 AM

    Briefing in #compliance

    Readiness, blockers, and the one thing to do next, posted where the team already reads.

    Readiness 84% · 1 blocker
  4. Every day

    Follow-ups sent for you

    Owners get a reminder before a test is due and an alert when it's late. Work nobody owns routes to the test's owner role.

    2 reminders · 1 SLA alert
  5. When a check fails

    Fix recommended

    Each failing check comes with the recommended fix and the steps to apply it. The finding closes on its own once the nightly re-check passes.

    Re-check passed · closed
  6. Audit window

    Signed pack assembled

    Policies, evidence, and a manifest. Your auditor verifies the signatures independently.

    SHA-256 · RFC 3161

Also included

Everything else in the box.

Trust Center, vendor management, questionnaires, and the rest. Included in the price, not sold as line items.

  • S3 buckets encrypted
    MFA on all admins
    CloudTrail retention 365d

    650+ automated checks

    Cloud, code, and identity scans on a schedule. One check counts toward every framework it maps to.

  • ppriya@acme.com
    ssam@acme.com
    aalex@acme.com

    People & training

    Onboarding, training, and policy acknowledgments per employee.

  • MacBook
    RDS
    S3

    Asset inventory

    Laptops, cloud resources, and SaaS accounts with owner and encryption state.

  • contractor@ext.io

    Admin · idle 71d

    KeepRevoke

    Access reviews

    Quarterly reviews pulled, routed for approval, and filed by Vera.

  • trust.acme.com Live
    SOC 2 Type II
    HIPAA

    Trust Center

    A public page built from live evidence. Prospects stop emailing for the report.

  • AWSLow
    OpenAIMedium
    StripeLow
    DatadogLow
    TwilioMedium

    Vendor risk

    Every vendor with a risk tier, DPA status, and their own SOC 2 report.

  • Do you encrypt data at rest?

    Yes. AES-256 on all RDS and S3.

    Sourced from CC6.7

    Security questionnaires

    Answers drafted from your controls, with the control ID attached.

  • Risk card

    RSK-002

    Ransomware on production

    Inherent 20 · Residual 8

    Risk register

    Findings from Wiz, CrowdStrike, AWS Security Hub, Snyk, and GitHub land here with severity and the affected system.

  • Auditor viewread-only
    Signed evidence pack
    Manifest verified

    Auditor portal

    A read-only view of controls, evidence, and the signed pack for the auditor you pick.

Review the evidence for yourself

Know what you’re connecting. See what your auditor receives.

Review our security practices, inspect how evidence is signed, and ask us to walk through an evidence export. Your audit firm stays independent.

Credentials never touch our database

Cloud provider keys live in Azure Key Vault, retrieved at scan time, never cached or logged. A breach of us is not a breach of you.

Read-only by construction

No write scopes on your repos or cloud. Source code is scanned in memory and never persisted. We cannot change your infrastructure, by design.

Evidence you can verify yourself

RSA/ECDSA signatures, RFC 3161 timestamps, SHA-256 manifests, BYOK. An open spec and a free verify CLI, no account needed.

Your compliance program

Know your next steps before you commit.

A free 30-minute readiness review with Screenata’s founder, based on your customer requirement, current setup, and target date. Get a written summary of scope, priority gaps, and next steps. No purchase or system access required.

Clear scope. Named responsibilities. A proposal in writing.

Agree the work before you start.

  • Your scope

    Frameworks, entities, infrastructure, and the deadline you’re working toward.

  • Our support

    Founder-led onboarding, a shared Slack channel, and a practical evidence plan.

  • Your proposal

    Platform, onboarding, responsibilities, and renewal terms agreed before signing.

  • Your auditor

    Choose and contract with an independent audit firm directly.

FAQ

Know what happens before you start.

The free review, human support, your responsibilities, and the work Vera handles.

What do I get in the free readiness review?

A free 30-minute readiness review with Screenata’s founder, based on your customer requirement, current setup, and target date. Get a written summary of scope, priority gaps, and next steps. No purchase or system access required. This is an initial review based on what you share, not an audit or a complete verification of your controls. If Screenata fits, we can also provide a scoped proposal.

Who helps us when we get stuck?

Your team gets a shared Slack channel with Screenata’s founder for setup questions, product help, and blockers. We agree support hours and check-in times during onboarding.

What will our team still need to do?

Your team connects systems, provides accurate information, reviews and approves policies, operates controls, and fixes infrastructure gaps. Screenata helps prepare policies, collect evidence, and organize the next actions. If you need hands-on implementation or specialist advice, we can discuss a separately scoped delivery partner engagement.

How long will our SOC 2 take?

We review your scope, existing controls, evidence gaps, and team availability before agreeing milestones. A SOC 2 Type II also requires an observation period agreed with your auditor. Your independent auditor determines whether the evidence is sufficient and issues the report; the free readiness review does not guarantee an audit outcome or completion date.

What makes Screenata different from Vanta or Drata?

Evaluate the work each product handles for your actual setup. Screenata combines infrastructure-grounded policies, evidence collection through integrations and guided procedures, and founder-led onboarding. Ask us to demonstrate one of your evidence tasks and clarify what your team still needs to do.

How are policies generated?

Screenata scans first, then writes. We pull context from GitHub, AWS or GCP, your IdP, existing evidence, and your company profile, then generate policies grounded in what we found. The overpromise checker flags hard commitments (like 'quarterly access reviews') we cannot verify in evidence, before you ever ship them to an auditor.

How do you collect evidence that integrations can't reach?

Three channels, not one. API scans cover about 30–40% of a SOC 2 across cloud, code, and identity providers. The browser extension captures screenshots of settings pages and workflows, redacts sensitive fields, runs a vision quality check, signs the capture, and re-captures it on a schedule. Guided procedures walk a teammate through steps like a backup restore test and record results and attachments as they work. Your team reviews the output and supplies context where a task requires human judgment.

How is our price determined?

We review your frameworks, entities, infrastructure, and support needs, then put the scope, price, and responsibilities in writing. The free readiness review has no purchase requirement. You choose and pay your independent auditor separately.

Do I need compliance expertise to use Screenata?

No. Every test explains what to provide, which evidence items are required, and how your auditor will judge it, and you can ask Vera about any requirement in plain language. The lineage view traces a policy, claim, control, or test through to the evidence that proves it, so you can see why something is required. When a check fails, it comes with the recommended fix and the steps to apply it, and the finding closes on its own once the nightly re-check passes.

Start with a free readiness review

Bring the customer request. Leave with next steps.

A free 30-minute readiness review with Screenata’s founder, based on your customer requirement, current setup, and target date. Get a written summary of scope, priority gaps, and next steps. No purchase or system access required.